CVE-2023-4973
Academy LMS GET Parameter filter cross site scripting
Record summary
CVE-2023-4973 has a selected CVSS score of 3.5 (low); EIP currently links 1 Nuclei template.
Description
A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument searched_word/searched_tution_class_type[]/searched_price_type[]/searched_duration[] leads to cross site scripting. The attack can be launched remotely. The identifier VDB-239749 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 16, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 6.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMAcademy LMS 6.2 - Cross-Site ScriptingCVSS 6.1
A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument searched_word/searched_tution_class_type[]/searched_price_type[]/searched_duration[] leads to cross site scripting. The attack can be launched remotely.
Impact
Unauthenticated attackers can inject malicious JavaScript via reflected XSS in search parameters, potentially stealing user session cookies or performing actions on behalf of users.
Remediation
Update Academy LMS to version 6.3 or later.
Source: ProjectDiscovery